CVE-2020-36919: WPForms 1.7.8 - Cross-Site Scripting (XSS)
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36919?
CVE-2020-36919 is classified as a high severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2020-36919?
To fix CVE-2020-36919, update WPForms to the latest version where the cross-site scripting vulnerability has been addressed.
What type of attack can be executed through CVE-2020-36919?
CVE-2020-36919 can allow attackers to execute arbitrary JavaScript code in a victim's browser through cross-site scripting (XSS).
Which versions of WPForms are affected by CVE-2020-36919?
CVE-2020-36919 specifically affects WPForms version 1.7.8.
What is the impact of CVE-2020-36919?
The impact of CVE-2020-36919 includes unauthorized script execution, which can lead to data theft, session hijacking, or other malicious activities.